Scan saved at 1:36:09 AM, on 8/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files\Sandboxie\SbieSvc.exeLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:36:09 AM, on 8/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sandboxie\SbieCtrl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Sandboxie\SandboxieRpcSs.exe
C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://asdfds/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sdafsdaf:80
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall Pro\ie_bar.dll
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O20 - AppInit_DLLs: c:\progra~1\agnitum\outpos~1\wl_hook.dll
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: QRK - Unknown owner - C:\DOCUME~1\FryPan\LOCALS~1\Temp\QRK.exe (file missing)
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
--
End of file - 4125 bytes
------------------------
I installed sandboxie because i saw sandbox.sys hooked in all my SSDT entries. Ive been dealing with this for a while. Formatting doesnt help.
Also everytime i shut down my background changes to the default one. Also, when i reformat my default icon for the start menu changes. Computer starts up on its own and shuts off randomly..
ComboFix 09-08-30.01 - FryPan 08/30/2009 22:24.4.1 - NTFSx86
Running from: c:\documents and settings\FryPan\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.dat
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.lan
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.msi
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.par
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.res
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\instance.dat
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\mia.lib
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\windows\Installer\451f5.msi
c:\windows\Installer\451f6.msp
c:\windows\Installer\451f7.msp
c:\windows\Installer\451f8.msp
c:\windows\Installer\451f9.msp
c:\windows\Installer\451fa.msp
c:\windows\Installer\451fb.msp
c:\windows\Installer\451fc.msp
c:\windows\Installer\451fd.msp
c:\windows\Installer\451fe.msp
c:\windows\Installer\4f8c132.msi
c:\windows\Installer\4f8c133.msp
c:\windows\Installer\4f8c134.msp
c:\windows\Installer\4f8c135.msp
c:\windows\Installer\4f8c136.msp
c:\windows\Installer\4f8c137.msp
c:\windows\Installer\4f8c138.msp
c:\windows\Installer\4f8c139.msp
c:\windows\Installer\4f8c13a.msp
c:\windows\Installer\4f8c13b.msp
c:\windows\Installer\4f8c1df.msi
c:\windows\Installer\4f8c1e0.msp
c:\windows\Installer\4f8c1e1.msp
c:\windows\Installer\4f8c1e2.msp
c:\windows\Installer\4f8c1e3.msp
c:\windows\Installer\4f8c1e4.msp
c:\windows\Installer\4f8c1e5.msp
c:\windows\Installer\4f8c1e6.msp
c:\windows\Installer\4f8c1e7.msp
c:\windows\Installer\4f8c1e8.msp
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\ss.exe
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
D:\csrss.exe
D:\explorer.exe
D:\lsass.exe
D:\services.exe
D:\smss.exe
D:\winlogon.exe
D:\wupdmgr.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-31 )))))))))))))))))))))))))))))))
.
2009-08-31 03:11 . 2009-08-31 03:11 -------- d-----w- c:\program files\Support Tools
2009-08-31 02:55 . 2009-08-31 02:55 -------- d-----w- c:\program files\WinDirStat
2009-08-31 02:55 . 2009-08-31 02:56 -------- d-----w- c:\program files\SysOrb Server
2009-08-31 02:47 . 2009-08-31 02:47 -------- d-----w- c:\program files\Certero
2009-08-31 02:38 . 2009-08-31 02:38 -------- d-----w- C:\removeit
2009-08-30 10:05 . 2009-08-30 10:06 -------- d-----w- c:\documents and settings\NetworkService\Application Data\VMware
2009-08-30 09:49 . 2009-08-30 09:49 -------- d-----w- c:\program files\Rpm
2009-08-30 09:16 . 2009-08-30 09:16 18272416 ----a-w- c:\documents and settings\All Users\Application Data\Appupdater\wireshark-win32-1.2.0.exe
2009-08-30 09:15 . 2009-08-30 09:15 -------- d-----w- c:\program files\JRE
2009-08-30 09:15 . 2009-08-30 09:15 -------- d-----w- c:\program files\OpenOffice.org 3
2009-08-30 09:06 . 2009-08-30 09:10 155255392 ----a-w- c:\documents and settings\All Users\Application Data\Appupdater\OOo_3.1.0_Win32Intel_install_wJRE_en-US.exe
2009-08-30 09:06 . 2009-08-30 09:30 1925024 ----a-w- c:\documents and settings\All Users\Application Data\Appupdater\install_flash_player.exe
2009-08-30 09:06 . 2009-08-30 09:06 939956 ----a-w- c:\documents and settings\All Users\Application Data\Appupdater\7z465.exe
2009-08-30 09:04 . 2009-08-30 09:04 -------- d-----w- c:\windows\quarantined
2009-08-30 09:04 . 2009-08-30 09:04 -------- d-----w- c:\program files\utils
2009-08-30 09:01 . 2009-08-30 09:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Appupdater
2009-08-30 09:01 . 2009-08-30 09:01 -------- d-----w- c:\documents and settings\FryPan\Application Data\gnupg
2009-08-30 09:00 . 2009-08-30 09:00 -------- d-----w- c:\documents and settings\All Users\Appupdater
2009-08-30 09:00 . 2009-08-31 02:49 -------- d-----w- c:\program files\GNU
2009-08-30 08:46 . 2009-08-30 08:46 -------- d-----w- c:\program files\Technology Pathways
2009-08-30 08:37 . 2009-08-30 08:44 -------- d-----w- c:\documents and settings\FryPan\Application Data\VMware
2009-08-30 08:29 . 2008-10-30 22:59 9600 ----a-r- c:\windows\system32\drivers\vmnetadapter.sys
2009-08-30 08:29 . 2008-10-30 22:59 5120 ----a-r- c:\windows\system32\vnetinst.dll
2009-08-30 08:29 . 2009-08-30 10:05 -------- d-----w- c:\documents and settings\All Users\Application Data\VMware
2009-08-30 08:28 . 2008-10-30 22:59 10240 ----a-r- c:\windows\system32\drivers\vmnet.sys
2009-08-30 08:20 . 2009-08-30 08:38 -------- d-----w- C:\Virtual Machines
2009-08-30 08:15 . 2009-08-30 08:37 -------- d-----w- C:\cygwin
2009-08-30 04:47 . 2009-08-30 04:47 -------- d-----w- c:\documents and settings\FryPan\Local Settings\Application Data\wj32
2009-08-30 04:38 . 2009-08-30 04:38 -------- d-----w- c:\program files\Process Hacker
2009-08-30 04:25 . 2009-08-30 04:28 -------- d-----w- C:\Lop SD
2009-08-28 07:05 . 2009-08-28 07:05 -------- d-----w- c:\documents and settings\FryPan\Local Settings\Application Data\Runscanner.net
2009-08-28 06:42 . 2009-08-28 06:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-08-28 06:11 . 2009-08-28 06:11 -------- d-----w- c:\program files\ESET
2009-08-28 05:57 . 2009-08-30 04:47 -------- d-----w- c:\program files\Deep System Explorer
2009-08-28 05:23 . 2009-08-28 05:23 -------- d-----w- C:\Sandbox
2009-08-28 05:22 . 2009-08-28 05:22 -------- d-----w- c:\program files\Sandboxie
2009-08-28 05:16 . 2009-08-28 05:16 -------- d-----w- c:\documents and settings\FryPan\Local Settings\Application Data\Help
2009-08-25 04:08 . 2009-08-25 04:08 8 ----a-w- c:\windows\system32\nvModes.dat
2009-08-25 00:10 . 2009-08-25 00:39 -------- d-----w- c:\documents and settings\FryPan\Local Settings\Application Data\Deployment
2009-08-21 15:18 . 2008-07-08 13:45 4984 ----a-w- c:\windows\system32\drivers\nvphy.bin
2009-08-21 15:07 . 2009-08-31 03:32 -------- d-----w- c:\windows\system32\CatRoot2
2009-08-21 14:51 . 2009-08-21 14:51 -------- d-----w- c:\documents and settings\FryPan\Application Data\DNTU
2009-08-21 14:49 . 2009-08-21 14:51 -------- d-----w- c:\documents and settings\FryPan\Application Data\DameWare Development
2009-08-21 14:33 . 2009-08-21 14:33 -------- d-----w- c:\documents and settings\FryPan\Local Settings\Application Data\Sophos
2009-08-21 14:22 . 2009-08-21 14:23 -------- dc-h--w- c:\windows\ie8
2009-08-21 13:47 . 2009-08-21 13:47 -------- d-----w- c:\program files\FrostWire
2009-08-21 13:17 . 2009-08-21 13:17 -------- d-----w- c:\documents and settings\FryPan\Application Data\SystemTools
2009-08-21 12:55 . 2009-08-21 12:55 152576 ----a-w- c:\documents and settings\FryPan\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-21 12:42 . 2009-08-21 12:42 70144 ----a-r- c:\documents and settings\FryPan\Application Data\Microsoft\Installer\{52D862F9-F281-41B5-8806-58D4ABB8159E}\IconA2E65BCA.exe
2009-08-21 12:42 . 2009-08-21 12:42 39936 ----a-r- c:\documents and settings\FryPan\Application Data\Microsoft\Installer\{52D862F9-F281-41B5-8806-58D4ABB8159E}\Icon1DEF20221.exe
2009-08-21 12:42 . 2009-08-21 12:42 -------- d-----w- c:\program files\DameWare Development
2009-08-21 12:11 . 2009-08-31 02:49 -------- d-----w- c:\documents and settings\FryPan\Application Data\eMule
2009-08-21 12:11 . 2009-08-21 12:11 -------- d-----w- c:\program files\eMule
2009-08-21 11:54 . 2009-08-23 09:54 15 ----a-w- c:\documents and settings\FryPan\settings.dat
2009-08-21 11:41 . 2009-08-21 11:41 -------- d-----w- c:\documents and settings\FryPan\Local Settings\Application Data\Identities
2009-08-21 11:34 . 2009-01-20 17:52 31928 ----a-w- c:\windows\system32\rrMon.sys
2009-08-21 11:34 . 2009-08-21 11:34 -------- d-----w- c:\program files\Registrar Registry Manager
2009-08-21 11:33 . 2009-08-21 11:33 -------- d-----w- c:\program files\SanityCheck
2009-08-21 11:33 . 2009-03-08 02:23 30136 ----a-w- c:\windows\system32\drivers\rspSanity32.sys
2009-08-21 11:27 . 2009-08-21 11:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Sophos
2009-08-21 11:27 . 2009-08-21 11:27 -------- d-----w- C:\stdtsa
2009-08-12 00:46 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-10 20:38 . 2009-08-10 20:38 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-04 20:49 . 2009-08-04 20:49 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-04 20:49 . 2009-07-03 14:49 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-08-04 20:38 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-04 20:38 . 2009-08-04 20:38 -------- dc----w- c:\windows\system32\DRVSTORE
2009-08-04 20:37 . 2009-08-04 20:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-04 20:37 . 2009-08-04 20:37 -------- d-----w- c:\program files\Lavasoft
2009-08-04 16:25 . 2005-08-30 20:19 1052672 ----a-w- c:\documents and settings\FryPan\Application Data\Macromedia\Dreamweaver 8\Configuration\Flash Player\FlashPlayerW.dll
2009-08-04 16:18 . 2009-08-04 16:37 -------- d-----w- c:\program files\Common Files\Macromedia
2009-08-04 16:18 . 2009-08-04 16:37 -------- d-----w- c:\program files\Macromedia
2009-08-04 16:18 . 2009-08-30 08:45 -------- d-----w- c:\windows\Downloaded Installations
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-31 03:23 . 2008-09-18 22:44 -------- d-----w- c:\documents and settings\FryPan\Application Data\uTorrent
2009-08-31 02:56 . 2008-09-05 11:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-30 10:15 . 2009-06-05 16:34 -------- d-----w- c:\documents and settings\FryPan\Application Data\FrostWire
2009-08-30 10:05 . 2008-09-19 04:54 -------- d-----w- c:\program files\7-Zip
2009-08-30 09:19 . 2008-09-05 12:06 19352 ----a-w- c:\documents and settings\FryPan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-30 09:14 . 2008-09-05 13:21 -------- d-----w- c:\program files\OpenOffice.org 2.3
2009-08-30 09:11 . 2008-09-05 13:20 -------- d-----w- c:\program files\Java
2009-08-30 04:54 . 2009-05-15 01:42 -------- d-----w- c:\program files\stea
2009-08-28 07:55 . 2008-09-05 13:55 -------- d-----w- c:\program files\Trillian
2009-08-28 05:16 . 2009-08-28 05:15 -------- d-----w- c:\program files\Security Task Manager
2009-08-28 05:16 . 2009-08-28 05:15 -------- d-----w- c:\documents and settings\All Users\Application Data\SecTaskMan
2009-08-25 04:12 . 2008-09-05 13:14 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-08-25 01:03 . 2008-12-24 20:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-25 01:03 . 2009-01-07 08:16 3942048 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-21 14:48 . 2008-10-24 23:13 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-21 14:19 . 2008-09-06 07:38 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-21 12:55 . 2009-06-05 14:13 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-21 10:51 . 2008-09-05 12:12 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 20:31 . 2008-09-05 12:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-03 18:36 . 2008-12-24 20:50 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 18:36 . 2008-12-24 20:50 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-26 04:13 . 2009-07-26 04:13 -------- d-----w- c:\program files\Realtek AC97
2009-07-26 04:01 . 2009-06-06 06:40 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-07-25 16:46 . 2009-06-06 07:05 -------- d-----w- c:\program files\NVIDIA Corporation
2009-07-25 16:46 . 2009-07-25 16:46 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-07-25 10:23 . 2009-01-07 21:05 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:01 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 18:54 . 2009-07-26 03:58 485920 ----a-w- c:\windows\system32\nvudisp.exe
2009-07-14 18:54 . 2009-07-26 03:58 2189856 ----a-w- c:\windows\system32\nvcuvid.dll
2009-07-14 18:54 . 2009-07-26 03:58 1706528 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-07-14 18:54 . 2009-07-26 03:58 2002944 ----a-w- c:\windows\system32\nvcuda.dll
2009-07-14 18:54 . 2009-07-26 03:58 1597690 ----a-w- c:\windows\system32\nvdata.bin
2009-07-14 18:35 . 2009-07-14 18:35 2173472 ----a-w- c:\windows\system32\nvcplui.exe
2009-07-14 04:43 . 2004-08-04 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 12:01 . 2009-07-26 03:58 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-07-03 17:09 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-08-04 12:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 12:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 12:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 12:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2004-08-04 12:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-17 04:59 . 2009-06-17 04:59 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-06-16 14:36 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2004-08-04 12:00 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-04 12:00 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2008-09-05 11:36 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2004-08-04 12:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2004-08-04 12:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-06 04:16 . 2009-06-06 04:16 290816 ----a-w- c:\documents and settings\FryPan\Application Data\SystemRequirementsLab\SRLProxy_nvd_4.dll
2009-06-06 04:16 . 2009-06-06 04:16 290816 ----a-w- c:\documents and settings\FryPan\Application Data\SystemRequirementsLab\SRLProxy_nvd_3.dll
2009-06-06 04:16 . 2009-06-06 04:16 290816 ----a-w- c:\documents and settings\FryPan\Application Data\SystemRequirementsLab\SRLProxy_nvd_2.dll
2009-06-06 04:16 . 2009-06-06 04:16 290816 ----a-w- c:\documents and settings\FryPan\Application Data\SystemRequirementsLab\SRLProxy_nvd_1.dll
2009-06-05 16:37 . 2009-06-05 16:37 0 ----a-w- c:\documents and settings\FryPan\Application Data\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
2009-06-03 19:09 . 2004-08-04 12:00 1291264 ----a-w- c:\windows\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2009-05-28 380416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2008-07-07 1158472]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-29 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-29 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-12-19 76304]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-06-29 1626112]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2006-08-03 577536]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)
"NoSimpleStartMenu"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"idsvc"=3 (0x3)
"NMIndexingService"=3 (0x3)
"LightScribeService"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"PLFlash DeviceIoControl Service"=2 (0x2)
"SharedAccess"=2 (0x2)
"UPS"=3 (0x3)
"helpsvc"=2 (0x2)
"FontCache3.0.0.0"=3 (0x3)
"xmlprov"=3 (0x3)
"Netlogon"=3 (0x3)
"SwPrv"=3 (0x3)
"HTTPFilter"=3 (0x3)
"ERSvc"=2 (0x2)
"MSDTC"=3 (0x3)
"aspnet_state"=3 (0x3)
"Dot3svc"=3 (0x3)
"rpcapd"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"nwiz"=nwiz.exe /install
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [8/4/2009 3:38 PM 64160]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [9/5/2008 6:53 AM 13696]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [5/18/2009 6:38 AM 672928]
R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [5/18/2009 6:37 AM 1238344]
R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;c:\program files\ASTRA32\astra32.sys [2/22/2007 11:28 AM 30864]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [3/11/2009 1:57 PM 10384]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [5/18/2009 6:37 AM 30864]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [5/18/2009 6:38 AM 234640]
R3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [5/18/2009 6:38 AM 33408]
R3 SbieDrv;SbieDrv;c:\program files\Sandboxie\SbieDrv.sys [5/28/2009 8:32 AM 108032]
S3 CMC AntiRootkit Service;CMC AntiRootkit Servic;c:\windows\system32\drivers\cmcantirootkit.sys --> c:\windows\system32\drivers\cmcantirootkit.sys [?]
S3 ffs;ffs;c:\documents and settings\FryPan\My Documents\Downloads\ffsdrv-0.5.1-winxp\ffs.sys [4/21/2007 9:15 PM 61312]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
S3 QRK;QRK;c:\docume~1\FryPan\LOCALS~1\Temp\QRK.exe --> c:\docume~1\FryPan\LOCALS~1\Temp\QRK.exe [?]
S3 rspSanity;rspSanity;c:\windows\system32\drivers\rspSanity32.sys [8/21/2009 6:33 AM 30136]
S3 VJHHXO;VJHHXO;c:\docume~1\FryPan\LOCALS~1\Temp\VJHHXO.exe --> c:\docume~1\FryPan\LOCALS~1\Temp\VJHHXO.exe [?]
S4 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2/27/2009 5:03 AM 603904]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyServer = sdafsdaf:80
FF - ProfilePath - c:\documents and settings\FryPan\Application Data\Mozilla\Firefox\Profiles\dfpjagct.default\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-30 22:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(388)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\msdtc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exep
c:\program files\Sandboxie\SbieSvc.exe
c:\program files\NVIDIA Corporation\System Update\UpdateCenterService.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2009-08-31 22:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-31 03:37
Pre-Run: 45,643,243,520 bytes free
Post-Run: 45,852,803,072 bytes free
378 --- E O F --- 2009-08-21 15:23
2009-08-31 03:27:57 . 2009-08-31 03:27:57 2,418 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_NPF.reg.dat
2009-08-31 03:27:57 . 2009-08-31 03:27:57 1,326 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_NPF.reg.dat
2009-08-31 03:27:46 . 2009-09-01 01:35:39 6,537 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2009-08-31 03:22:57 . 2009-09-01 01:31:52 235 ----a-w- C:\Qoobox\Quarantine\catchme.log
2009-08-04 20:38:06 . 2009-08-04 20:38:06 90 -c--a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\instance.dat.vir
2009-08-04 20:38:06 . 2009-08-04 20:38:20 494 -c--a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.dat.vir
2009-08-04 20:38:06 . 2009-08-04 20:38:06 9 -c--a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.lan.vir
2009-08-04 20:38:06 . 2009-08-04 20:38:06 4,509 -c--a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.par.vir
2009-08-04 20:38:06 . 2009-07-08 17:28:46 578,782 -c--a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\mia.lib.vir
2009-08-04 20:38:06 . 2009-07-08 17:28:50 14,540,833 -c--a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.res.vir
2009-08-04 20:38:05 . 2009-07-08 17:28:44 1,860,608 -c--a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.msi.vir
2009-08-04 20:38:05 . 2009-07-08 17:28:49 2,920,112 -c--a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe.vir
2009-02-13 20:07:52 . 2009-02-13 20:07:52 88,576 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c1df.msi.vir
2008-07-29 23:45:28 . 2008-07-29 23:45:28 2,543,616 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\451f6.msp.vir
2008-07-29 23:45:28 . 2008-07-29 23:45:28 2,543,616 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c133.msp.vir
2008-07-29 23:45:28 . 2008-07-29 23:45:28 2,543,616 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c1e8.msp.vir
2008-07-29 23:43:22 . 2008-07-29 23:43:22 1,013,248 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\451fb.msp.vir
2008-07-29 23:43:22 . 2008-07-29 23:43:22 1,013,248 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c138.msp.vir
2008-07-29 23:43:22 . 2008-07-29 23:43:22 1,013,248 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c1e3.msp.vir
2008-07-29 23:41:16 . 2008-07-29 23:41:16 6,487,040 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\451f8.msp.vir
2008-07-29 23:41:16 . 2008-07-29 23:41:16 6,487,040 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c135.msp.vir
2008-07-29 23:41:16 . 2008-07-29 23:41:16 6,487,040 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c1e6.msp.vir
2008-07-29 23:39:14 . 2008-07-29 23:39:14 3,403,264 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\451f9.msp.vir
2008-07-29 23:39:14 . 2008-07-29 23:39:14 3,403,264 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c136.msp.vir
2008-07-29 23:39:14 . 2008-07-29 23:39:14 3,403,264 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c1e5.msp.vir
2008-07-29 23:37:12 . 2008-07-29 23:37:12 911,360 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\451fd.msp.vir
2008-07-29 23:37:12 . 2008-07-29 23:37:12 911,360 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c13a.msp.vir
2008-07-29 23:37:12 . 2008-07-29 23:37:12 911,360 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c1e1.msp.vir
2008-07-29 23:35:10 . 2008-07-29 23:35:10 553,472 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\451fa.msp.vir
2008-07-29 23:35:10 . 2008-07-29 23:35:10 553,472 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c137.msp.vir
2008-07-29 23:35:10 . 2008-07-29 23:35:10 553,472 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c1e4.msp.vir
2008-07-29 23:33:08 . 2008-07-29 23:33:08 506,368 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\451fc.msp.vir
2008-07-29 23:33:08 . 2008-07-29 23:33:08 506,368 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c139.msp.vir
2008-07-29 23:33:08 . 2008-07-29 23:33:08 506,368 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c1e2.msp.vir
2008-07-29 23:31:06 . 2008-07-29 23:31:06 6,083,072 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\451fe.msp.vir
2008-07-29 23:31:06 . 2008-07-29 23:31:06 6,083,072 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c13b.msp.vir
2008-07-29 23:31:06 . 2008-07-29 23:31:06 6,083,072 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c1e0.msp.vir
2008-07-29 23:29:04 . 2008-07-29 23:29:04 2,926,080 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\451f7.msp.vir
2008-07-29 23:29:04 . 2008-07-29 23:29:04 2,926,080 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c134.msp.vir
2008-07-29 23:29:04 . 2008-07-29 23:29:04 2,926,080 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c1e7.msp.vir
2008-07-29 23:27:32 . 2008-07-29 23:27:32 93,184 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\451f5.msi.vir
2008-07-29 23:27:32 . 2008-07-29 23:27:32 93,184 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4f8c132.msi.vir
2007-11-06 20:23:18 . 2007-11-06 20:23:18 240,248 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\wpcap.dll.vir
2007-11-06 20:22:30 . 2007-11-06 20:22:30 68,224 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\WanPacket.dll.vir
2007-11-06 20:22:26 . 2007-11-06 20:22:26 92,792 ----a-w- C:\Qoobox\Quarantine\C\Program Files\WinPcap\rpcapd.exe.vir
2007-11-06 20:22:20 . 2007-11-06 20:22:20 88,696 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\Packet.dll.vir
2007-11-06 20:22:06 . 2007-11-06 20:22:06 34,064 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\npf.sys.vir
2007-11-06 20:19:28 . 2007-11-06 20:19:28 53,299 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\pthreadVC.dll.vir
2004-08-04 12:00:00 . 2008-04-14 00:12:34 31,232 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\ss.exe.vir